Skip to main content
The Audit screen is the organisation-wide audit trail — who changed what, when, from where, and what each value was before — across every record in the product. The Audit screen, showing the busiest record types and people and the latest events The Audit screen, showing the busiest record types and people and the latest events Open it from Setup → Audit in the navigation, or from the Audit card in Administration. The menu item only appears for people who can read the audit trail. Individual records — an asset, a site, a work order — also have their own history tab; this screen is for the questions that do not start from one record: who changed anything last Tuesday, what did this person touch before they left, show me every deletion.

What is recorded

The product writes an event whenever a record is created, changed or deleted, and for actions such as signing in. Each event records: Nobody can edit or delete an audit event, from this screen or anywhere else. The trail is kept in monthly sections; the stat strip says how many it holds.

The stat strip

Narrowing the trail

Every search is bounded by its dates — the dates decide how much of the trail is read, so narrow them first for a fast answer. Clear filters removes them all. On a phone the filters are behind Filters, closed with Done.

The overview

While only the dates are set, two panels summarise the period: Busiest record types and Busiest people, each with a count. They cover the dates only, so they are hidden as soon as you narrow anything else, and a note says so (“Narrowed — the totals above cover the dates only”). If nothing in the period was done by a person, the people panel says every event was written by the product itself.

What happened

The list of events, newest first, with a count. Each event shows its summary, who did it, when, its action and record type, and three links: An audit event opened to compare a field before and after An audit event opened to compare a field before and after The list loads 100 events at a time; Show {n} more loads the next, or export the period to read the rest. The footer says how many are shown and for which dates. An empty answer says which kind it is: “Nothing matches” when your filters exclude everything — the trail is complete for the period, this is an empty answer, not a missing one — or “Nothing was recorded in these dates” when the period itself is empty.

Exporting

Export downloads the trail for the period as a CSV file, with the columns When, Record type, Record, Action, Who, From, Fields changed, What happened and Reason. An export carries the dates, the record type and the person — nothing else. If you have set an action, a source, a field or a text search, a note above the list says the file would be wider than the list on screen. An export stops at 10,000 events; if it reaches that, a warning asks you to narrow the dates and take it again. To send the trail to your security team’s SIEM continuously, see security events.

Who can use this screen

Somebody without Audit · view who opens the address is told that reading the whole trail needs the audit permission; the history tab on a record they can already see is unaffected.